A $1.4 million official White House app is raising serious security concerns after researchers discovered it contains code from Elfsight, a Russia-founded vendor. Federal employees, including those at the Federal Aviation Administration (FAA), are required to install the app on government-issued mobile devices, but the presence of Russian-origin software components has sparked debate over transparency and approval procedures.
Elfsight: Russian origins and growth despite sanctions
Elfsight was founded in 2016 in Tula, Russia, by CEO Andrey Yusupov and CTO Vladimir Fedotov. Today, the company markets itself as a European software provider headquartered in Andorra, but its original Russian entity remains active and growing. In 2025, the Russian branch reported revenue of approximately 126.5 million rubles ($1.6 million), a 71% increase year-over-year. Headcount rose to 61 employees, and job postings in 2026 continued to recruit Russian developers, including a Moscow-based support specialist offering 60,000–100,000 rubles per month. These persistent ties raise questions, as Russian law can compel companies handling user data to store it locally and hand it over to state authorities.
Sponsored Protocol
Security analysis: cookies and scripts under external control
A network analysis by security firm Atomic Computer revealed that Elfsight's servers determine which JavaScript files run inside the White House app. The same session accepted more than ten cookies from Elfsight, alongside Google DoubleClick ad domains loaded through the app's YouTube sections. White House spokesperson Olivia Wales said the app "does not request or collect any user locations" and that all information is "safe and secure." A White House official later clarified that the only remaining Elfsight script loads a tax calculator inside a sandboxed webview, disconnected from cookies or files. However, that security clearance sits uneasily alongside evidence that Elfsight's founders retained accounts at sanctioned Russian banks and continued traveling to Russia.
Sponsored Protocol
National security implications and transparency
The incident highlights potential gaps in government app security reviews. While Elfsight claims it has "never received any request" from Russian authorities for user data, the country's legal framework could enable forced access. With US sanctions in place since 2022, the approval of an app with such ties appears controversial. Related articles, such as the one on LG monitors silently installing adware, show how external code can compromise security. For more details on Elfsight, see the original TechRadar article. The question remains why an app with such ties was cleared for use on federal devices.
Sponsored Protocol